Welcome!

Cloud Security Authors: Liz McMillan, Scott Millis, Elizabeth White, Kevin Jackson, Doron Kolton

Related Topics: @CloudExpo, Cloud Security, Government Cloud

@CloudExpo: Article

Is Cloud Computing for Real?

Summary of Session by CIO of the National Reconnaissance Office at Cloud Expo New York

In October 2009, Enterprise Cloud Computing was considered bleeding edge technology by many but there was something that seemed different about its value potential and adoption rate. For CIOs, it seemed a chance to provision affordable infrastructure quickly, alleviating delays to mission critical deliveries. Federal CIOs interest in Enterprise Cloud Computing was limited to innovators and early adopters. Two years later, where does Enterprise Cloud Computing stand? Is it for real?



Today, Cloud Computing is on the Gartner® technology hype curve in the “peak of inflated expectations” category. Its placement on the curve—even though we all should prepare for the dreaded “trough of disillusionment” dip—indicates Cloud Computing is, indeed, for real. There are other indicators of note also. CIOs across the board are focused on the success Cloud Computing can deliver. Vendors are sparring with each other to obtain space in Gartner’s Magic Quadrant. The Federal CIO has issued a “Cloud First” policy and published the first Federal Cloud Computing Strategy. And, it’s been featured in the hit comic strip Dilbert—a pop culture indicator worth noting!

Federal agencies need IT solutions that can handle current missions—from supporting counter-terrorism to combating proliferation of weapons of mass destruction--and we need IT that can handle global surge demands based on fluctuating world events and natural disasters. Federal IT must be efficiently adaptable and properly affordable to meet evolving mission needs. It must be capable of keeping pace with the exponential growth of data, including the increasing complexities of maintaining legal and regulatory compliance of information management and assurance.

As a CIO, building your cloud strategy can be confusing as there are many options to consider before making a decision. Cloud Computing can deliver within a variety of characteristics. Each CIO will need to consider the characteristics of primary importance in order to properly center a strategy. For example, determining your needs for rapid elasticity, on-demand self-service, global access, and payment options will be necessary to develop the right strategy. The second consideration for a CIO is just how far up the stack she wants to go. Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) each deliver different features and capabilities for your business. You can develop a plan that includes some or all of the Services. Finally, a CIO needs to think about the deployment model(s) that best fit her business (Public, Private, Community, and Hybrid).

Cloud Computing isn’t perfect; there are concerns to manage and mistakes to avoid. The number one concern remains Security and that’s given rise to Enterprise Cloud Computing deployments and private clouds. But, there are other concerns also such as the skill set of your workforce, requirements for compliance verification, legacy baseline migration, and costs. For example, depending on the percentage of your legacy that can successfully transition to Cloud, your cost-benefit equation may not provide sufficient return for the investment.

Common mistakes to avoid include: assuming Cloud Computing is for everything; planning for a “light switch” migration from legacy to new; selecting only one vendor and creating early lock-in; underestimating the cultural change required by your own IT team; and implementing a bunch of mini- clouds in your existing data closets.

We’ve spent 18 months developing the National Reconnaissance Office (NRO) IT strategy and roadmap; we gave it a lot of thought but it is just an example and not the only way to move forward. Our cloud delivery model will be private first and then a hybrid of private and community (with our Intelligence Community colleagues). We’re moving our way up the stack starting with IaaS and PaaS first, then SaaS. And, we are focused on a phased revolutionary approach—building a new environment as a green field.

Our planning has highlighted the need to focus attention on management of the NRO Cloud. Defining specific roles and responsibilities, articulating cloud service level agreements between the provider and users, adjusting organizational constructs to fit the Cloud business model, and streamlining configuration control processes to meet the rapid timelines of provisioning must all be addressed if success is to be achieved. Our planning also indicated the NRO mission would not be served by a CPU-based commodity cloud alone. We also need a high-performance cloud that is GPU-based and we are learning there are industry gaps in this area.

The NRO Cloud strategy won’t be too different from how other Federal agencies adopt Cloud Computing. Most agencies processing classified information are focused on private clouds versus public clouds for security and information management/assurance reasons. Over time, though, I believe federal community clouds will emerge, as will private hybrid clouds, which allow agencies to maintain a private space as well as take advantage of federal community clouds.

The NRO Cloud will be implemented in four phases over the course of 6 years. It’s a complex migration necessarily paced to meet federal budget processes, existing acquisition commitments, and mission service imperatives.

  • Phase 1 – Test It. We have multiple small cloud pilots ongoing covering commodity/utility cloud, high performance cloud, and big data cloud. We are focused on streamlining information assurance compliance, developing appropriate policies and processes, and defining standards.
  • Phase 2 – Prove It. In this phase, we will merge successful elements from Phase 1, finalize policies, prototype management and governance changes necessary for cloud provisioning models, refine standards, realign programs as needed, and ensure enterprise foundation capabilities meet mission demands.
  • Phase 3 – Use It. Scaled deployment of the enterprise Cloud will occur. Applications will develop specific transition and migration plans generally aligned with planned refresh cycles. Service management processes and new centralized information assurance approaches will be refined for long-term success.
  • Phase 4 – Exploit It. The NRO Cloud will emerge as the primary Enterprise Infrastructure Services Provider with robust measures of effectiveness, performance accountability, and service transparency. New mission and business applications will emerge through innovations in Cloud Computing and federation with the IC Cloud will be achieved moving the NRO into a hybrid environment.

In summary, the time for Cloud Computing is now. All of the indicators are in place to suggest a rapid and successful migration to this newest generation of IT architecture. It is not a one-size-fits-all migration. CIOs will need to spend time exploring Cloud Computing solutions to find the combination that best responds to specific mission and business needs. Maintaining awareness of the concerns and mistakes is absolutely necessary and security remains the top concern. Security is a huge focus for IT vendors and creative, robust solutions will be constantly emerging to reduce concerns. Large organizations will increasingly turn to Enterprise Cloud Computing strategies to achieve efficiencies of Cloud Computing while reducing risks of exposure for intellectual property, customer privacy, and competitive strategies.

More Stories By Jill Tummler Singer

Jill Tummler Singer is CIO for the National Reconnaissance Office (NRO)- which as part of the 16-member Intelligence Community plays a primary role in achieving information superiority for the U.S. Government and Armed Forces. A DoD agency, the NRO is staffed by DoD and CIA personnel. It is funded through the National Reconnaissance Program, part of the National Foreign Intelligence Program.

Prior to joining the NRO, Singer was Deputy CIO at the Central Intelligence Agency (CIA), where she was responsible for ensuring CIA had the information, technology, and infrastructure necessary to effectively execute its missions. Prior to her appointment as Deputy CIO, she served as the Director of the Diplomatic Telecommunications Service (DTS), United States Department of State, and was responsible for global network services to US foreign missions.

Singer has served in several senior leadership positions within the Federal Government. She was the head of Systems Engineering, Architecture, and Planning for CIA's global infrastructure organization. She served as the Director of Architecture and Implementation for the Intelligence Community CIO and pioneered the technology and management concepts that are the basis for multi-agency secure collaboration. She also served within CIA’s Directorate of Science and Technology.

Comments (1) View Comments

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


Most Recent Comments
Elad Israeli 06/20/11 08:48:00 AM EDT

I can relate to many points you list here. I come from the business intelligence space, where the Cloud and SaaS are way overly hyped - mainly due to some startups in the space.

http://tinyurl.com/saas-bi

@ThingsExpo Stories
Internet-of-Things discussions can end up either going down the consumer gadget rabbit hole or focused on the sort of data logging that industrial manufacturers have been doing forever. However, in fact, companies today are already using IoT data both to optimize their operational technology and to improve the experience of customer interactions in novel ways. In his session at @ThingsExpo, Gordon Haff, Red Hat Technology Evangelist, will share examples from a wide range of industries – includin...
We're entering the post-smartphone era, where wearable gadgets from watches and fitness bands to glasses and health aids will power the next technological revolution. With mass adoption of wearable devices comes a new data ecosystem that must be protected. Wearables open new pathways that facilitate the tracking, sharing and storing of consumers’ personal health, location and daily activity data. Consumers have some idea of the data these devices capture, but most don’t realize how revealing and...
Unless your company can spend a lot of money on new technology, re-engineering your environment and hiring a comprehensive cybersecurity team, you will most likely move to the cloud or seek external service partnerships. In his session at 18th Cloud Expo, Darren Guccione, CEO of Keeper Security, revealed what you need to know when it comes to encryption in the cloud.
"We build IoT infrastructure products - when you have to integrate different devices, different systems and cloud you have to build an application to do that but we eliminate the need to build an application. Our products can integrate any device, any system, any cloud regardless of protocol," explained Peter Jung, Chief Product Officer at Pulzze Systems, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
In his general session at 19th Cloud Expo, Manish Dixit, VP of Product and Engineering at Dice, discussed how Dice leverages data insights and tools to help both tech professionals and recruiters better understand how skills relate to each other and which skills are in high demand using interactive visualizations and salary indicator tools to maximize earning potential. Manish Dixit is VP of Product and Engineering at Dice. As the leader of the Product, Engineering and Data Sciences team at D...
Data is the fuel that drives the machine learning algorithmic engines and ultimately provides the business value. In his session at 20th Cloud Expo, Ed Featherston, director/senior enterprise architect at Collaborative Consulting, will discuss the key considerations around quality, volume, timeliness, and pedigree that must be dealt with in order to properly fuel that engine.
In addition to all the benefits, IoT is also bringing new kind of customer experience challenges - cars that unlock themselves, thermostats turning houses into saunas and baby video monitors broadcasting over the internet. This list can only increase because while IoT services should be intuitive and simple to use, the delivery ecosystem is a myriad of potential problems as IoT explodes complexity. So finding a performance issue is like finding the proverbial needle in the haystack.
According to Forrester Research, every business will become either a digital predator or digital prey by 2020. To avoid demise, organizations must rapidly create new sources of value in their end-to-end customer experiences. True digital predators also must break down information and process silos and extend digital transformation initiatives to empower employees with the digital resources needed to win, serve, and retain customers.
"Once customers get a year into their IoT deployments, they start to realize that they may have been shortsighted in the ways they built out their deployment and the key thing I see a lot of people looking at is - how can I take equipment data, pull it back in an IoT solution and show it in a dashboard," stated Dave McCarthy, Director of Products at Bsquare Corporation, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
Fact is, enterprises have significant legacy voice infrastructure that’s costly to replace with pure IP solutions. How can we bring this analog infrastructure into our shiny new cloud applications? There are proven methods to bind both legacy voice applications and traditional PSTN audio into cloud-based applications and services at a carrier scale. Some of the most successful implementations leverage WebRTC, WebSockets, SIP and other open source technologies. In his session at @ThingsExpo, Da...
@GonzalezCarmen has been ranked the Number One Influencer and @ThingsExpo has been named the Number One Brand in the “M2M 2016: Top 100 Influencers and Brands” by Onalytica. Onalytica analyzed tweets over the last 6 months mentioning the keywords M2M OR “Machine to Machine.” They then identified the top 100 most influential brands and individuals leading the discussion on Twitter.
Today we can collect lots and lots of performance data. We build beautiful dashboards and even have fancy query languages to access and transform the data. Still performance data is a secret language only a couple of people understand. The more business becomes digital the more stakeholders are interested in this data including how it relates to business. Some of these people have never used a monitoring tool before. They have a question on their mind like “How is my application doing” but no id...
As data explodes in quantity, importance and from new sources, the need for managing and protecting data residing across physical, virtual, and cloud environments grow with it. Managing data includes protecting it, indexing and classifying it for true, long-term management, compliance and E-Discovery. Commvault can ensure this with a single pane of glass solution – whether in a private cloud, a Service Provider delivered public cloud or a hybrid cloud environment – across the heterogeneous enter...
"IoT is going to be a huge industry with a lot of value for end users, for industries, for consumers, for manufacturers. How can we use cloud to effectively manage IoT applications," stated Ian Khan, Innovation & Marketing Manager at Solgeniakhela, in this SYS-CON.tv interview at @ThingsExpo, held November 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA.
"We're a cybersecurity firm that specializes in engineering security solutions both at the software and hardware level. Security cannot be an after-the-fact afterthought, which is what it's become," stated Richard Blech, Chief Executive Officer at Secure Channels, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
Information technology is an industry that has always experienced change, and the dramatic change sweeping across the industry today could not be truthfully described as the first time we've seen such widespread change impacting customer investments. However, the rate of the change, and the potential outcomes from today's digital transformation has the distinct potential to separate the industry into two camps: Organizations that see the change coming, embrace it, and successful leverage it; and...
Data is the fuel that drives the machine learning algorithmic engines and ultimately provides the business value. In his session at Cloud Expo, Ed Featherston, a director and senior enterprise architect at Collaborative Consulting, discussed the key considerations around quality, volume, timeliness, and pedigree that must be dealt with in order to properly fuel that engine.
We are always online. We access our data, our finances, work, and various services on the Internet. But we live in a congested world of information in which the roads were built two decades ago. The quest for better, faster Internet routing has been around for a decade, but nobody solved this problem. We’ve seen band-aid approaches like CDNs that attack a niche's slice of static content part of the Internet, but that’s it. It does not address the dynamic services-based Internet of today. It does...
Internet of @ThingsExpo, taking place June 6-8, 2017 at the Javits Center in New York City, New York, is co-located with the 20th International Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. @ThingsExpo New York Call for Papers is now open.
What happens when the different parts of a vehicle become smarter than the vehicle itself? As we move toward the era of smart everything, hundreds of entities in a vehicle that communicate with each other, the vehicle and external systems create a need for identity orchestration so that all entities work as a conglomerate. Much like an orchestra without a conductor, without the ability to secure, control, and connect the link between a vehicle’s head unit, devices, and systems and to manage the ...